Newsletter Signup
Where current and emerging technology trends meet.
TecTrendsInformation Sources, Inc.
  | About TecTrends | Email Signup | Contact Us
 Live Search:
Live Search | Articles | Companies | TecTerms | Products
  Loading TecTrends Live Search - please wait... 
View Noteworthy Articles      PRNewswire
 
Article

Title: Taking Aim: Target-based IDSes squelch network noise to pinpoint...

Author: Snyder, Joel Article Type: Product Comparison
Source: Information Security, v7 n1 p34(11) Publication Date: Jan 2004
  ISSN: 1096-8903
  Illustrations: Charts; Buyers Guides
URL of Publication: http://www.infosecuritymag.com

Network intrusion detection systems (NIDSes) often generate false alerts, reducing their usefulness. Target-based IDS is a new approach that focuses on detecting specific threats to known network features. Three target-based products are Cisco Systems' Cisco Threat Response 2.0 (CRT), Internet Security Systems' (ISS) Site Protector Security Fusion Module 2.0, and Tenable Network Security's Lightning Console 2.0. IDS noise reduction is the goal of all three programs. CTR has a flawed architecture, which Cisco is redesigning, and is reactive rather than proactive at detection. Fusion is difficult to set up, but has many useful tools. Lightning Console has both active and passive scanning capabilities, but has some drawbacks with respect to classifying vulnerabilities. All three reduce IDS noise, with Lightning Console providing the most noise reduction benefit, and CRT the least. Fusion has a good scanner, but uses a traditional approach that has limitations. CTR is better at verifying vulnerabilities than scanning, but does catch some threats that the other systems do not. It can, however, be a denial-of-service threat itself. Lightning has the most aggressive and comprehensive scanning capabilities. It also has the easiest-to- use tuning tools, but tuning is limited for all three applications. Target-based IDS is a new technology that offers some improvements over traditional IDS, but still has a number of drawbacks.

Special Features: Charts; Buyers Guides

Companies:
Cisco Systems Inc Internet Security Systems Inc (ISS)
Tenable Network Security Inc

Products:
Cisco Threat Response Lightning Console
Site Protector Security Fusion Module

TecTerms:


[Get Copyright Permissions] Click here for copyright permissions!
Copyright 2004-2008 Information Sources Inc.
 


Home About TecTrends About Us Contact Us Privacy Statement Terms and Conditions

TecTrends | P.O. Box 8120 | Berkeley CA 94707 | (510) 525-6220 | Email: tectrends@tectrends.com
© 2006 INFORMATION SOURCES INC | All rights reserved.